PCI Internal Security Assessor
hace 4 días
Job Overview
The PCI Internal Security Assessor (ISA) is responsible for ensuring that our client from banking industry complies with the Payment Card Industry Data Security Standard (PCI DSS). The ISA will assess, monitor, and enforce the security measures necessary to protect cardholder data and maintain PCI compliance across all systems and processes. This role works closely with internal stakeholders and external parties to maintain a secure environment, mitigate risks, and improve overall security posture.
Key Responsibilities:- PCI DSS Compliance Management:
- Conduct regular internal assessments and audits to ensure the organization's compliance with PCI DSS.
Develop and implement PCI compliance policies, procedures, and controls.
- Serve as the internal point of contact for PCI DSS-related matters and ensure all applicable security controls are in place.
- Collaborate with the external Qualified Security Assessor (QSA) to facilitate annual PCI DSS certification audits.
Documentation and Reporting:
- Prepare and maintain comprehensive documentation, including policies, procedures, and reports required for PCI DSS compliance.
- Maintain comprehensive documentation of assessment findings, corrective actions, and compliance status.
- Manage the submission of the Self-Assessment Questionnaires (SAQs) and Attestation of Compliance documents (AOCs) as needed.
Education:
- Bachelors degree in Information Security, Computer Science, or a related field (or
equivalent work experience).
- Experience:
- Minimum of 3-5 years of experience in information security, PCI compliance, or a related field.
- Previous experience as an ISA, QSA, or a similar role is highly desirable.
- Certifications:
- Certified PCI Internal Security Assessor (ISA) or Certified PCI Professional (PCIP) certifications preferred.
Additional certifications such as CISSP, CISM, CISA, or CEH are a plus.
- Skills and Competencies:
- Deep understanding of PCI DSS requirements and data security best practices.
- Familiarity with security frameworks (NIST, ISO 27001, CIS Controls) and security technologies (firewalls, IDS/IPS, encryption, etc.).
- Strong analytical, problem-solving, and project management skills.
- Excellent communication and interpersonal skills with the ability to work cross- functionally.
- Proficiency in using security assessment tools and techniques (e.g., vulnerability scanners, SIEM).
Ability to work independently and handle sensitive information confidentially.
- Detail-oriented with strong organizational skills.
- Occasional travel may be required for audits or compliance reviews.
- Identify and assess potential risks to cardholder data environments and provide recommendations for risk mitigation.
- Implement and enforce necessary security controls to address gaps identified during assessments.
- Ensure vulnerability scanning, penetration testing, and security reviews are conducted to identify weaknesses and ensure continuous compliance.
- Conduct internal PCI DSS training for staff to ensure a deep understanding of the importance of compliance and security measures.
- Provide ongoing guidance and support to departments regarding security best practices related to PCI DSS.
- Work closely with projects, Enterprise Security, Technology, and other relevant departments to align PCI DSS compliance with overall security policies and practices.
- Proactively identify and/or promptly escalate risks and issues affecting PCI compliance status.
- Stay updated on changes in PCI DSS requirements and industry best practices to ensure our client from banking industry remains compliant.
- Present PCI DSS compliance status reports to senior management and external stakeholders.
- Act as a liaison where necessary between our client from banking industry and external vendors or service providers involved in processing or storing cardholder data.
-
PCI Internal Security Assessor
hace 5 días
Port of Spain thehivecareers A tiempo completoJob Overview The PCI Internal Security Assessor (ISA) is responsible for ensuring that our client from banking industry complies with the
-
Cyber Security Analyst
hace 8 horas
Port of Spain, Trinidad and Tobago thehivecareers A tiempo completoAbout the job Cyber Security AnalystThe Cyber Security Analyst will be responsible for protecting all of the company's hardware, software, and networks from cybercriminals. The analyst's primary role will be to understand the company IT infrastructure in detail in order to detect, evaluate and respond to threats that could potentially breach the network. The...
-
Técnico/a Sistemas PCI
hace 9 horas
Villares de la Reina, Castilla and Leon, España Chubb Fire & Security A tiempo completoEn Chubb nos superamos constantemente y fomentamos una cultura de liderazgo en la que las personas entusiastas y motivadas pueden destacar en todos los ámbitos de su vida. Junto con nuestra empresa matriz, APi Group, en Chubb creemos que todo el mundo puede ser un líder.¿Quieres trabajar con nosotros?Estamos en la búsqueda de una persona como Técnico/a...
-
Technical Support Officer
hace 11 horas
Port of Spain, Trinidad and Tobago thehivecareers A tiempo completoAbout the job Technical Support OfficerPOSITION: Technical Support Officer SECTION/UNIT: TechnologyReports to: Chief Technology OfficerSupervises: N/AJOB PURPOSEThe Technical Support Officer implements and supports cloud-based solutions for messaging, collaboration, endpoint management and related security policies. The incumbent will also act as the first...
-
QA Automation
hace 9 horas
Port of Spain, Trinidad and Tobago thehivecareers A tiempo completoAbout the job QA AutomationJob briefThe ideal candidate will review the requirements, specifications and technical design documents to provide timely and meaningful feedback to clients.ResponsibilitiesCreate detailed, comprehensive and well structured test plans andtest cases.Estimate, prioritize, plan and coordinate testing activities.Design, develop and...
-
Data Engineer
hace 7 días
Port of Spain, Trinidad and Tobago thehivecareers A tiempo completoJob Summary:The data engineer designs and develops data models, collects and analyzes data for insights and communicates how those findings improve reliability, customer experience, profitability and other relevant factors. He / She also captures, transforms and stores clean data, leaving it ready for consumption.This role will be integral in ensuring the...
-
Security Analyst Tier 1
hace 2 semanas
Spain Kudelski Security A tiempo completoPLEASE SUBMIT YOUR CV IN ENGLISH.Revise detenidamente toda la documentación de la solicitud antes de hacer clic en el botón de solicitar al final de esta descripción.Stimulating. Motivating. Challenging.Leveraging its long-standing expertise in securing digital content as well as fighting piracy, Kudelski Security, a division of the Kudelski Group, is a...
-
Cyber Security Consultant
hace 2 semanas
Madrid, Community of Madrid, , Spain Integrity360 A tiempo completoRole: Cyber Risk & Assurance Consultant Location: Madrid, hybridAbout Integrity360Integrity360 is the largest independent cyber security provider in Europe, with a growing international presence spanning the UK, Ireland, mainland Europe, Africa and the Caribbean. With over 700 employees, across 12 locations, and six Security Operations Centres...
-
Cyber Security Specialist
hace 1 semana
Spain 83zero A tiempo completoPrisma Access Consultant ¿Todo listo para enviar su solicitud? Por favor, lea la descripción al menos una vez antes de hacer clic en "Solicitar".Location: Spain (Remote / Hybrid) Contract Length: 12 months 83zero are working in partnership with a global cyber security leader to support a major secure access and cloud security transformation programme...
-
Information Security Associate Director – IT
hace 2 semanas
Spain Headhunting Firm A tiempo completoOur executive search firm is partnering with a leading international pharmaceutical company headquartered in Barcelona to appoint an Information Security Associate Director to further strengthen its global cybersecurity capabilities within a complex, industrial and highly regulated environment. La experiencia que se espera de los solicitantes, así como las...